This is a simple container running Zeek with a direct feed into LimaCharlie which allows you to quickly deploy Zeek sensors and get retention, alerting and forwarding in the cloud.
This container is available on Docker Hub as refractionpoint/lc-adapter-zeek.
User needs to define the following environment variables:
OID = The LimaCharlie Organization IDIKEY = The LimaCharlie Installation KeyNAME = A unique name for the sensorOptional environment variables:
IFACE = The interface to listen on (default: eth0)ZEEK_ARGS = Additional arguments to pass to ZeekExample command line with Docker:
docker run -it -e OID=aaaaaaaa-bfa1-bbbb-cccc-138cd51389cd -e IKEY=aaaaaaaa-9ae6-bbbb-cccc-5e42b854adf5 -e NAME=zeek -e IFACE=eth0 refractionpoint/lc-adapter-zeek
Content type
Image
Digest
sha256:7fd014100…
Size
239.1 MB
Last updated
11 days ago
docker pull refractionpoint/lc-adapter-zeek